/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Some ransomware rings have started stealing data before they encrypt to use stolen data as leverage, ensuring that even victims with backups make the payment

Ransomware operators stealing data before they encrypt means backups are not enough.  —  Not every ransomware attack is an unmitigated disaster.

Ars Technica Sean Gallagher

Context & Ripple Effects

This story closes the loop on an escalation that began years ago, when skilled attackers started using evolved crypto-ransomware to turn every network intrusion into a potential payday (every intrusion a payday). The new wrinkle reported here is sequencing: exfiltration before encryption, so the stolen copy itself becomes the hostage.

That move lands on an ecosystem already primed to pay. ProPublica found US data recovery firms marketing 'hi-tech' decryption while quietly just paying ransoms and marking up the bill (recovery firms that paid ransoms), and cyber insurers often preferring to settle in ransom even when backups could restore files, to save claim costs (insurers preferring to pay). Exfiltration-first tactics make those payment paths harder to avoid.

First-order effects

  • Victims with verified backups lose their main escape hatch: restoring systems no longer undoes the breach, because the stolen data can still be published or sold if they refuse to pay.
  • Cyber insurers and incident responders face a changed negotiation — the insurer's cost-saving preference for paying ransoms now applies even to clients whose backup posture would previously have argued for restoration instead.

Second-order effects

  • Data recovery firms that resell ransom payments as 'decryption services' take on added exposure, since a successful file restore no longer ends the victim's crisis and the firm's promise of resolution becomes harder to sell.
  • Security tooling built around detecting encryption's heavy file I/O misses the quieter exfiltration phase that precedes it — a gap later exploited by gangs using intermittent encryption to evade exactly those detectors (intermittent encryption evading detection).

Third-order effects

  • If the pattern holds, ransomware stops being purely an availability problem and becomes a data-breach problem, pulling every attack into breach-notification, disclosure, and regulatory territory regardless of whether systems are restored.
  • The economics of extortion shift from 'how good are your backups' to 'how much is your data worth public,' which pressures buyers toward prevention and egress monitoring rather than recovery — reshaping what cyber insurance underwrites and what security budgets prioritize.

The trend: Ransomware is evolving from single-leverage encryption into layered extortion where stolen data, not locked files, is the primary collateral — making payment pressure independent of victims' recovery capability.